CVE-2026-94510

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Full discourse1 post
  • Dark Web Intelligence@DailyDarkWeb

    ⚠️ MICROSOFT DISCLOSES 5 CRITICAL CLOUD-SERVICE FLAWS — PARTNER CENTER RATED CVSS 10.0 Microsoft published five critical CVEs on Oct 8 affecting hosted Microsoft services: • CVE-2026-96207 (CVSS 10.0) Partner Center: improper certificate validation, unauthenticated network privilege escalation • CVE-2026-94510 (CVSS 9.9) Bookings: authorization bypass via user-controlled key • CVE-2026-77900 (CVSS 9.8) Azure App Service for Linux: missing authentication, code execution • CVE-2026-88131 (CVSS 9.8) Dataverse: deserialization of untrusted data, RCE • CVE-2026-69435 (CVSS 9.6) Azure SRE Agent: missing authorization, privilege escalation by an authenticated attacker Fixes are deployed on Microsoft's side; no public exploit or in-the-wild exploitation reported so far. Admins should review MSRC entries for any tenant-side guidance. Primary: msrc[.]microsoft[.]com/update-guide/vulnerability/CVE-2026-96207 #DDW #DarkWeb #Microsoft #Azure #CVE #CloudSecurity #CyberSecurity

    0201654.4K
    207.7K followersView on X

Explore more